AWS Security ChangesHomeSearch

AWS singlesignon: Include account access manager in ABAC documentation

Service: singlesignon · 2026-08-11 · Documentation medium

File: singlesignon/latest/userguide/configure-abac-policies.md · Type: authz

Summary

Updated ABAC policy guidance to reference account access manager IAM roles.

Security assessment

Clarifies ABAC implementation for IAM roles in account access manager.

Evidence

+You can use access control attributes in your permission sets (or IAM roles when using account access manager) using the `aws:PrincipalTag` condition key for creating access control rules.

Diff

diff --git a/singlesignon/latest/userguide/configure-abac-policies.md b/singlesignon/latest/userguide/configure-abac-policies.md
index 6fd80faf9..1bf71cbd3 100644
--- a//singlesignon/latest/userguide/configure-abac-policies.md
+++ b//singlesignon/latest/userguide/configure-abac-policies.md
@@ -15 +15 @@ You can create permissions policies that determine who can access your AWS resou
-You can use access control attributes in your permission sets using the `aws:PrincipalTag` condition key for creating access control rules. For example, in the following policy you can tag all the resources in your organization with their respective cost centers. You can also use a single permission set that grants developers access to their cost center resources. Now, whenever developers federate into the account using single sign-on and their cost center attribute, they only get access to the resources in their respective cost centers. As the team adds more developers and resources to their project, you only have to tag resources with the correct cost center. Then you pass cost center information in the AWS session when developers federate into AWS accounts. As a result, as the organization adds new resources and developers to the cost center, developers can manage resources aligned to their cost centers without needing any permission updates.
+You can use access control attributes in your permission sets (or IAM roles when using account access manager) using the `aws:PrincipalTag` condition key for creating access control rules. For example, in the following policy you can tag all the resources in your organization with their respective cost centers. You can also use a single permission set (or IAM role when using account access manager) that grants developers access to their cost center resources. Now, whenever developers federate into the account using single sign-on and their cost center attribute, they only get access to the resources in their respective cost centers. As the team adds more developers and resources to their project, you only have to tag resources with the correct cost center. Then you pass cost center information in the AWS session when developers federate into AWS accounts. As a result, as the organization adds new resources and developers to the cost center, developers can manage resources aligned to their cost centers without needing any permission updates.